2026 CVE Vulnerabilities
53,163 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2738 | MEDIUM | 5.6 | 0.1% | Feb 19, 2026 | Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packet... |
| CVE-2026-27440 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ... |
| CVE-2026-27387 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configu... |
| CVE-2026-27368 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd comi... |
| CVE-2026-27360 | MEDIUM | 5.9 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Galler... |
| CVE-2026-27328 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in DevsBlink EduBlink edublink allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-27327 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in YayCommerce YayMail yaymail allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-27014 | MEDIUM | 5.5 | 0.2% | Feb 19, 2026 | NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOff... |
| CVE-2026-26312 | MEDIUM | 6.5 | 0.4% | Feb 19, 2026 | Stalwart is a mail and collaboration server. A denial-of-service vulnerability exists in Stalwart Mail Server versions 0... |
| CVE-2026-26282 | MEDIUM | 6.6 | 0.2% | Feb 19, 2026 | NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an ou... |
| CVE-2026-27013 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | Fabric.js is a Javascript HTML5 canvas library. Prior to version 7.2.0, Fabric.js applies `escapeXml()` to text content ... |
| CVE-2026-26203 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer und... |
| CVE-2026-26193 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.... |
| CVE-2026-26192 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.... |
| CVE-2026-27474 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | SPIP before 4.4.9 allows Cross-Site Scripting (XSS) in the private area, complementing an incomplete fix from SPIP 4.4.8... |
| CVE-2026-27473 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | SPIP before 4.4.9 allows Stored Cross-Site Scripting (XSS) via syndicated sites in the private area. The #URL_SYNDIC out... |
| CVE-2026-27472 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | SPIP before 4.4.9 allows Blind Server-Side Request Forgery (SSRF) via syndicated sites in the private area. When editing... |
| CVE-2026-26059 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | ChurchCRM is an open-source church management system. In versions prior to 6.8.2, it was possible for an authenticated u... |
| CVE-2026-23621 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the L... |
| CVE-2026-2817 | MEDIUM | 4.8 | 0.1% | Feb 19, 2026 | Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directorie... |
| CVE-2026-2243 | MEDIUM | 5.1 | 0.1% | Feb 19, 2026 | A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially ... |
| CVE-2026-23620 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListSe... |
| CVE-2026-23619 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains se... |
| CVE-2026-23618 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che... |
| CVE-2026-23617 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Che... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now